΢Èí°ä²¼12Ô·ݵݲȫ¸üУ¬£¬£¬£¬ £¬×ܼƽ¨¸´49¸ö·ì϶

°ä²¼¹¦·ò 2022-12-14
1¡¢Î¢Èí°ä²¼12Ô·ݵݲȫ¸üУ¬£¬£¬£¬ £¬×ܼƽ¨¸´49¸ö·ì϶

      

12ÔÂ13ÈÕ£¬£¬£¬£¬ £¬Î¢Èí°ä²¼Öܶþ²¹¶¡£¡£¡£¡£¡£¬£¬£¬£¬ £¬½¨¸´ÁËÔ̺¬Ò»¸öÒѱ»¼«ÀûÓõķì϶ÔÚÄÚµÄ49¸ö·ì϶¡£¡£¡£¡£¡£Õâ´Î¸üн¨¸´ÁËÁ½¸öÁãÈÕ·ì϶£¬£¬£¬£¬ £¬±ðÀëΪWindows SmartScreen°²È«Ö°ÄÜÈÆ¹ý·ì϶£¨CVE-2022-44698£©£¬£¬£¬£¬ £¬¹¥»÷ÕßÄܹ»Í¨¹ýÔì×÷Ò»¸ö¶ñÒâÎļþÀ´ÈƹýMOTW·ÀÓù£»£»£»£»£»ÒÔ¼°DirectXͼÐÎÄÚºËȨÏÞÌáÉý·ì϶£¨CVE-2022-44710£©£¬£¬£¬£¬ £¬³É¹¦ÀûÓô˷ì϶¿É»ñµÃSYSTEMȨÏÞ¡£¡£¡£¡£¡£ÆäÖУ¬£¬£¬£¬ £¬·ì϶CVE-2022-44698Òѱ»»ý¼«ÀûÓᣡ£¡£¡£¡£


https://www.bleepingcomputer.com/news/microsoft/microsoft-december-2022-patch-tuesday-fixes-2-zero-days-49-flaws/


2¡¢UberÒòµÚÈý·½¹©¸øÉÌÔâµ½¹¥»÷Ô´´úÂëºÍÔ±¹¤ÐÅÏ¢µÈй¶

      

¾ÝýÌå12ÔÂ12ÈÕ±¨Â·£¬£¬£¬£¬ £¬ºÚ¿ÍUberLeaksÔÚÂÛ̳Éϰ䲼ÁË´ÓUberºÍUber EatsÇÔÈ¡µÄÊý¾Ý¡£¡£¡£¡£¡£Ð¹Â¶µÄÊý¾ÝÔ̺¬Ô´´úÂë¡¢IT×ʲúÖÎÀí»ã±¨¡¢Êý¾ÝÏú»Ù»ã±¨¡¢WindowsÓòµÇ¼ÃûÒÔ¼°³¬¹ý77000¸öUberÔ±¹¤µÄÐÅÏ¢µÈ¡£¡£¡£¡£¡£×êÑÐÈËÔ±×î³õÒÔΪÕâЩÊý¾ÝÊÇÔÚ9Ô·ݵĹ¥»÷ÊÂÎñÖб»µÁµÄ£¬£¬£¬£¬ £¬µ«Uber°µÊ¾ÕâÓëµÚÈý·½¹©¸øÉ̵ݲȫ·ì϶ÓйØ¡£¡£¡£¡£¡£Uber°µÊ¾£¬£¬£¬£¬ £¬ÓÃÓÚ×ʲúÖÎÀíºÍ¸ú×Ù·þÎñµÄTeqtivityÔâµ½¹¥»÷£¬£¬£¬£¬ £¬¹¥»÷Õß»ñµÃÁËÆäΪ¿Í»§´æ´¢Êý¾ÝµÄTeqtivity AWS±¸·Ý·þÎñÆ÷µÄ½Ó¼ûȨÏÞ¡£¡£¡£¡£¡£


https://www.bleepingcomputer.com/news/security/uber-suffers-new-data-breach-after-attack-on-vendor-info-leaked-online/


3¡¢ÀÕË÷ÍÅ»ïLockBit³ÆÒÑ´Ó¼ÓÖݲÆÕþ²¿ÇÔÈ¡76 GBµÄÊý¾Ý

      

¾Ý12ÔÂ12ÈÕ±¨Â·£¬£¬£¬£¬ £¬LockBitÐû³ÆÒÑÈëÇÖ¼ÓÀû¸£ÄáÑÇÖݵIJÆÕþ²¿£¬£¬£¬£¬ £¬²¢ÇÔÈ¡ÁËÊý¾Ý¿â¡¢»úÃÜÊý¾Ý¡¢²ÆÕþÎļþºÍITÓйصÄÎļþ¡£¡£¡£¡£¡£¹¥»÷Õß»¹°ä²¼ÁËĿ¼ºÍ´æ´¢ÎļþÊýÁ¿µÄ½ØÍ¼£¬£¬£¬£¬ £¬ÏÔʾ³¬¹ý114000¸öÎļþ¼ÐÖÐÓг¬¹ý246000¸öÎļþ£¬£¬£¬£¬ £¬×ܼÆ75.3GBµÄÊý¾Ý¡£¡£¡£¡£¡£Ä¿Ç°£¬£¬£¬£¬ £¬LockBitÒªÇóµÄÊê½ð½ð¶îÉв»Ã÷ÏÔ£¬£¬£¬£¬ £¬µ«ÊÇÆäÍøÕ¾µÄµ¹¼ÆÊ±ÏÔʾҪÔÚ12ÔÂ24ÈÕ֮ǰ¸¶¡£¡£¡£¡£¡£¼ÓÖÝÖݳ¤´¹Î£·þÎñ°ì¹«ÊÒ°µÊ¾£¬£¬£¬£¬ £¬¼ÓÖÝÍøÂ簲ȫ¼¯³ÉÖÐÐÄ£¨Cal-CSIC£©ÔÚ»ý¼«Ó¦¶Ô´ËÊÂÎñ£¬£¬£¬£¬ £¬µ«Ã»ÓÐÌṩ̫¶àϸ½ÚÐÅÏ¢¡£¡£¡£¡£¡£


https://www.cyberscoop.com/lockbit-ransomware-california-department-of-finance/


4¡¢Ó¡¶È±í½»²¿µÄÍøÕ¾Ð¹Â¶±í¼®ÈËÊ¿»¤ÕÕ¾ßÌåÐÅÏ¢µÈÄÚÈÝ

      

ýÌå12ÔÂ12Èճƣ¬£¬£¬£¬ £¬Ó¡¶È±í½»²¿µÄGlobal Pravasi Rishta PortalÍøÕ¾Ð¹Â¶ÁË±í¼®ÈËÊ¿µÄ»¤ÕÕ¾ßÌåÐÅÏ¢¡£¡£¡£¡£¡£ÕâÊÇÒ»¸öÖ¼ÔÚÏνÓ3000ÍòÓ¡¶ÈÍâÇÈµÄÆ½Ì¨£¬£¬£¬£¬ £¬ÒÔÃ÷ÎĵĴó¾Ö¹«¿ªÁËÐÕÃû¡¢¾Óס¹ú¶ÈÓʼþµØÖ·¡¢Ö°ÒµÇé¿ö¡¢µç»°ºÍ»¤ÕÕºÅÂëµÈÐÅÏ¢¡£¡£¡£¡£¡£Ð¹Â¶Ô­Òò¿ÉÄÜÊǰ²È«´ëÊ©²»¼°£¬£¬£¬£¬ £¬ÀýÈç²»×ãÉí·ÝÑéÖ¤²½Öè¡£¡£¡£¡£¡£CybernewsÒÑÁªÏµ±í½»²¿·î¸æÆäй¶ÊÂÎñ£¬£¬£¬£¬ £¬²¢Ã»ÓÐÊÕµ½»Ø¸´£¬£¬£¬£¬ £¬µ«¸ÃÎÊÌâÔÚ¼¸ÌìºóµÃµ½Ïàʶ¾ö¡£¡£¡£¡£¡£


https://securityaffairs.co/wordpress/139561/data-breach/indian-foreign-ministrys-global-pravasi-rishta-portal-leaks-expat-passport-details.html


5¡¢Check Point°ä²¼¹ØÓÚÀÕË÷Èí¼þAzovµÄÉî¶È·ÖÎö»ã±¨

      

Check Point ResearchÔÚ12ÔÂ12ÈÕ°ä²¼Á˹ØÓÚÀÕË÷Èí¼þAzovµÄÉî¶È·ÖÎö»ã±¨¡£¡£¡£¡£¡£AzovÊ×ÏÈ×÷Ϊ½©Ê¬ÍøÂçSmokeLoaderµÄpayloadÒýÆð×êÑÐÈËԱȷ°ÑÎÈ£¬£¬£¬£¬ £¬ËüÓëͨ³£ÀÕË÷Èí¼þµÄÇø±ðÖ®Ò»ÊÇËüÅú¸ÄÁËijЩ64λ¿ÉÖ´ÐÐÎļþÀ´Ö´ÐÐ×Ô¼ºµÄ´úÂë¡£¡£¡£¡£¡£ÕâÖÖ¶ÔÖ¸±êµÄ¿ÉÖ´ÐÐÎļþµÄÇÖÂÔÐÔ¶à̬ϰȾµ¼Ö´óÁ¿¹«¿ª¿ÉÓõÄÎļþ±»AzovϰȾ£¬£¬£¬£¬ £¬Ã¿Ìì¶¼º±¼û°Ù¸öеÄAzovÓйØÑù±¾±»Ìá½»µ½VirusTotal¡£¡£¡£¡£¡£½ØÖÁ2022Äê11Ô£¬£¬£¬£¬ £¬¸ÃÑù±¾ÒѾ­³¬¹ý17000¸ö¡£¡£¡£¡£¡£


https://research.checkpoint.com/2022/pulling-the-curtains-on-azov-ransomware-not-a-skidsware-but-polymorphic-wiper/


6¡¢Unit 42°ä²¼½üÆÚеÄKerberos¹¥»÷·½Ê½µÄ·ÖÎö»ã±¨

      

12ÔÂ12ÈÕ£¬£¬£¬£¬ £¬Unit 42°ä²¼Á˽üÆÚеÄKerberos¹¥»÷·½Ê½µÄ·ÖÎö»ã±¨¡£¡£¡£¡£¡£Active DirectoryµÄ¿í·ºÊ¹ÓÃʹKerberos¹¥»÷³ÉΪºÜ¶à¹¥»÷ÕßµÄÖØÒª¼¿Á©£¬£¬£¬£¬ £¬×êÑÐÈËÔ±·¢ÏÖÁËÐµĹ¥»÷¼¼Êõ£¬£¬£¬£¬ £¬Diamond TicketºÍSapphire Ticket£¬£¬£¬£¬ £¬Ê¹¹¥»÷Õß¿ÉÄܲ»ÊÜÏ޶ȵؽӼûADÓòÖеÄËùÓзþÎñºÍ×ÊÔ´¡£¡£¡£¡£¡£Sapphire Ticket¹¥»÷±ØÒª»ñÈ¡ÓòÖÐÓû§µÄÍ´´¦£¬£¬£¬£¬ £¬¶øºóÀûÓÃÍ´´¦»ñÈ¡TGT£¬£¬£¬£¬ £¬²¢½«ÆäÓÃÓÚ½âÃܸßȨÏÞÓû§µÄPAC¡£¡£¡£¡£¡£Diamond Ticket¹¥»÷Ê×ÏÈÊÇ»ñÈ¡TGT£¬£¬£¬£¬ £¬¶øºóʹÓÃKRBTGTÕÊ»§µÄÃÜÔ¿½âÃÜTGT²¢Åú¸ÄTicket£¬£¬£¬£¬ £¬ÌáÉýȨÏÞ¡£¡£¡£¡£¡£


https://unit42.paloaltonetworks.com/next-gen-kerberos-attacks/